# Integrate PRTG with Active Directory

By default, PRTG uses its own internal user account database to authenticate users. For many PRTG  
customers, particularly those with smaller networks, this local authentication meets all their needs.

But for PRTG customers who have more complex environments and infrastructures or who want to reduce the number of authentication mechanisms in their networks, PRTG offers Active Directory (AD) integration as well.

This way, all members of the AD user groups that are mapped to user groups in PRTG during the integration can log in to PRTG with their AD domain credentials afterward.

<div class="pageelement active color-white fullwidth" id="bkmrk-"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-08" id="bkmrk--1"></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-black-blue fullwidth" id="bkmrk--2"><div class="arrow">  
</div><div class="groupsegment-body"><a name="prepare"></a><div class="tabsegment"></div></div></div><a name="database"></a>

## 1. Prepare your Active Directory for PRTG integration

<div class="pageelement active color-black-blue fullwidth" id="bkmrk--4"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-12" id="bkmrk--5"></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-grey-10 arrow-black-blue color-white fullwidth" id="bkmrk-%C2%A0"><div class="arrow"> </div><div class="groupsegment-body"><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-12" id="bkmrk--6"></div><div class="pageelement active col-06" id="bkmrk--7"><div class="imageelement lightbox">[![Active Directory users and computers](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/new_ad-prepare.jpg)](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/new_ad-prepare.jpg)</div></div><div class="pageelement active col-06">  
</div></div></div></div>In the AD, make sure that users who require the same [access rights](https://www.paessler.com/manuals/prtg/user_access_rights) for PRTG are in the same AD user group.

In our example, the AD user group *PRTG\_ADM* contains the two administrator user accounts that later have administrative rights in PRTG and that can also manage access rights and cluster setups and change the monitoring configuration of PRTG. The AD user group *PRTG\_RO* contains the four user accounts that later have only read access rights in PRTG.

<div class="pageelement active color-grey-10 arrow-black-blue color-white fullwidth" id="bkmrk--8"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-06" id="bkmrk--9"></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-black-blue fullwidth" id="bkmrk-%C2%A0-1"><div class="arrow"> </div><div class="groupsegment-body"><a name="prepareserver"></a><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-12">  
</div></div></div></div><a name="prepareserver"></a>

## 2. Prepare your PRTG core server system

<div class="pageelement active color-black-blue fullwidth" id="bkmrk--11"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-12" id="bkmrk--12"></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-white arrow-black-blue fullwidth" id="bkmrk-%C2%A0-2"><div class="arrow"> </div><div class="groupsegment-body"><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-03" id="bkmrk--13"></div><div class="pageelement active col-06">  
</div></div></div></div>Make sure that the PRTG core server system is a member of the AD domain with which you want to integrate it. You can check and, if necessary, change this setting via the Windows **Control Panel**:

<div class="pageelement active color-white arrow-black-blue fullwidth" id="bkmrk-navigate-to%C2%A0system.-"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-06" id="bkmrk-navigate-to%C2%A0system.--1">1. Navigate to **System**.
2. Go to section **Computer name, domain, and workgroup settings**.
3. Check the settings **Full computer name** and **Domain**.

</div></div><div class="clear">  
</div></div></div><div class="pageelement active color-black-blue fullwidth" id="bkmrk-%C2%A0-3"><div class="arrow"> </div><div class="groupsegment-body"><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-12">  
</div></div></div></div><a name="database"></a>

## 3. Add Active Directory domain details to PRTG

<div class="pageelement active color-black-blue fullwidth" id="bkmrk--15"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-12" id="bkmrk--16"></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-grey-10 arrow-black-blue fullwidth" id="bkmrk-%C2%A0-4"><div class="arrow"> </div><div class="groupsegment-body"><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-06" id="bkmrk--17"><div class="imageelement lightbox">[![Active Directory domain details](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/review082021/newer_ad-domain-details.jpg)](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/review082021/newer_ad-domain-details.jpg)</div></div><div class="pageelement active col-06"><div>  
</div></div></div></div></div>In the next step, you need to provide your local AD domain details in PRTG:

<div class="pageelement active color-grey-10 arrow-black-blue fullwidth" id="bkmrk-open-the-prtg-web-in"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-06" id="bkmrk-open-the-prtg-web-in-1"><div>1. Open the PRTG web interface and select **Setup** | **System Administration** |  
    **Core &amp; Probes** from the main menu.
2. Go to section **Active Directory Integration** and enter your local AD domain name in the **Domain Name** field.
3. Choose your preferred **LDAP Connection Security**
4. Under **Access Type**, select **Use explicit credentials** to define the Windows service account that PRTG uses to authenticate against the AD.  
    ![additional info manual](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/backups/additional-info_manual.svg) The service account must have the **Read permissions**, **Read all properties**, and **List contents** permissions for all your AD user groups.
5. Under **User Name**, enter the service account name that PRTG uses to access the AD.
6. Under **Password**, enter the respective password of the service account.
7. Click **Save**.

</div></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-black-blue fullwidth" id="bkmrk-%C2%A0-5"><div class="arrow"> </div><div class="groupsegment-body"><a name="usergroup"></a><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-12">  
</div></div></div></div><a name="database"></a>

## 4. Add new user groups in PRTG

<div class="pageelement active color-black-blue fullwidth" id="bkmrk--19"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-12" id="bkmrk--20"></div></div><div class="clear">  
</div></div></div><div class="pageelement active color-white arrow-black-blue fullwidth" id="bkmrk-%C2%A0-6"><div class="arrow"> </div><div class="groupsegment-body"><div class="tabsegment"><div class="tabsegment-tabs">  
</div></div><div class="segments-not-tabs"><div class="pageelement active col-12">  
</div></div></div></div><div class="pageelement active color-white arrow-black-blue fullwidth" id="bkmrk-in-the-prtg-web-inte"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-12" id="bkmrk--21"></div><div class="pageelement active divider3" id="bkmrk--22"><div class="divider-top">  
</div><div class="divider-bottom">  
</div></div><div class="pageelement active col-06"><div>1. In the PRTG web interface, select **Setup** | **System Administration** | **User Groups** from the main menu.
2. Hover over ![step2 pluszeichenflietext](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/msp/step2-pluszeichenflietext.jpg) and select **Add User Group**.
3. Provide a meaningful **User Group Name**.
4. Under **Administrative Rights**, select **Give user group members administrative rights**.
5. Under **Active Directory or Single Sign-On Integration**, select **Use Active Directory integration**.
6. Under **Active Directory Group**, select the AD user group whose members later have access to PRTG. For our example, we chose the *PRTG\_ADM* user group.  
    ![additional info manual](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/backups/additional-info_manual.svg) For very large ADs, you see an input field instead of a dropdown list when you add or modify a user group. In this case, you can only enter the AD user group name. PRTG automatically adds the prefix.

</div></div></div></div></div>Repeat these steps for the *PRTG\_RO* user group to create a second group of users that have only read access rights for PRTG. In this case, leave the default setting under **Administrative Rights**.

Now, members of the defined AD groups can log in to PRTG with the respective access rights.

<div class="pageelement active color-white arrow-black-blue fullwidth" id="bkmrk--23"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-06" id="bkmrk--24"><div>  
</div></div><div class="pageelement active col-06" id="bkmrk--25"><div class="imageelement lightbox">[![Add new user group](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/review082021/newer_ad-new-user-group.jpg)](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/review082021/newer_ad-new-user-group.jpg)</div></div><div class="pageelement active divider3" id="bkmrk--26"><div class="divider-top">  
</div><div class="divider-bottom">  
</div></div><div class="pageelement active col-06">  
</div></div></div></div>In the device tree, PRTG automatically creates new groups with the name *\[group\_name\] home* for each of the integrated AD user groups.

Do not forget to set [group access rights](https://www.paessler.com/manuals/prtg/user_access_rights#group_overview) that apply to device tree objects as well as to libraries, maps, and reports. You can do so in an object’s settings in section **Access Rights**.

The easiest way is to set group access rights in the settings of the root group.

<div class="pageelement active color-white arrow-black-blue fullwidth" id="bkmrk-prtg-active-director"><div class="groupsegment-body"><div class="segments-not-tabs"><div class="pageelement active col-06" id="bkmrk--27"><div class="imageelement lightbox">[![New ](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/new_ad-home-group.jpg)](https://hlassets.paessler.com/common/files/screenshots/prtg-v17-4/how-to-guides/02_active-directory/new_ad-home-group.jpg)</div></div></div></div><div class="imageelement lightbox">PRTG Active Directory Network</div></div>